Skip to main content

AP® Cybersecurity Unit 5 flashcardsSecuring Applications and Data

40 cards · about 10 minutes for the whole deck

Flashcard drill

Space flips the card, arrow keys move, and keys 1 to 4 rate how well you knew it.

Position
1 / 40
Due
40
Mastered
0 / 40
Saved on this device · Sign in to sync

This card: New

Something wrong with this card?

What's wrong?

Please don't include personal details.

Flip the card before you rate it.

  • Administrative privileges

    Admin accounts can change system settings and reach almost any file. If a regular user has admin rights and is compromised, so is the whole system.

    Topic 5.1: Application and Data Vulnerabilities and Attacks

  • Data validation

    Checking that user input matches what's expected, like a number for a quantity, and rejecting anything else before processing it.

    Topic 5.1: Application and Data Vulnerabilities and Attacks

  • SQL injection

    Putting SQL commands and control characters into an input field so the database returns too much data or changes or deletes data.

    Topic 5.1: Application and Data Vulnerabilities and Attacks

  • Cross-site scripting (XSS)

    Injecting malicious code into a website so visitors' browsers run it. It can reach data stored in the browser, like logins.

    Topic 5.1: Application and Data Vulnerabilities and Attacks

  • Reflected vs. stored XSS

    Reflected (Type I) XSS hides the code in a link the victim clicks. Stored (Type II) XSS saves it on the site, like in a comment, so every visitor runs it.

    Topic 5.1: Application and Data Vulnerabilities and Attacks

  • Buffer overflow

    Sending more data than a fixed-size memory buffer holds, so it spills into nearby memory. It can crash a system or run unauthorized code.

    Topic 5.1: Application and Data Vulnerabilities and Attacks

  • Directory traversal

    Changing a URL or GET request with ../ sequences to climb out of the web folder and reach sensitive files on the server.

    Topic 5.1: Application and Data Vulnerabilities and Attacks

  • Data states

    At rest (stored on a drive), in transit (moving between devices) and in use (being processed). Data must be decrypted to be used.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Personally identifiable information (PII)

    Data that can identify a person, like name, address, Social Security number, birthdate or email. Protected by laws like the Privacy Act of 1974.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Protected health information (PHI)

    Data about a person's health, treatment or health care payments, like test results. Protected under HIPAA (1996).

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Payment card information (PCI)

    Data used to process card payments: name, account number, expiration date, address and CVV code. Regulated by the PCI DSS industry standard.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Role-based access control (RBAC)

    Each user gets a role, and each role gets certain access, like only accountants using payroll software.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Rule-based access control (RuBAC)

    Access is allowed or denied by rules, like no database access outside working hours. Usually layered on another model.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Discretionary access control (DAC)

    Owners decide who can access the objects they own, like sharing a file with one person to edit and another to view. Admins can override.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Mandatory access control (MAC)

    Strict rules, set by an outside administrator, control access by levels given to users and objects, as in military classification.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Bell-LaPadula model

    A MAC model: you can't read objects above your level or write to objects below it. Summed up as "write up, read down."

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Least privilege

    Giving every user or program exactly the access it needs to do its job, and no more.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Linux file permissions

    Read (r), write (w) and execute (x), set for the owner, the group and others in that order, like rwxr-x---. A dash means no permission.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • chmod (numeric)

    chmod ### file sets owner, group and others with one digit each: read 4, write 2, execute 1. chmod 640 file gives rw-r-----.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • chmod (symbolic)

    chmod with u, g, o or a, then + or -, then r, w or x. chmod g+r file adds read for the group; chmod o-w file removes write for others.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • ls -l and getfacl

    ls -l shows a file's permissions. A + at the end means extra permissions are set, which you can see with getfacl.

    Topic 5.2: Protecting Applications and Data: Managerial Controls and Access Controls

  • Plaintext and ciphertext

    Plaintext is the readable information you encrypt. Ciphertext is the scrambled output of the encryption algorithm.

    Topic 5.3: Protecting Stored Data with Cryptography

  • Symmetric encryption

    Encryption that uses the same key to encrypt and decrypt. Both sides need that key.

    Topic 5.3: Protecting Stored Data with Cryptography

  • Block vs. stream cipher

    A block cipher encrypts fixed-size chunks of bits. A stream cipher encrypts a continuous flow, one element at a time.

    Topic 5.3: Protecting Stored Data with Cryptography

  • AES

    The Advanced Encryption Standard, the most common symmetric cipher. It encrypts 128-bit blocks and can use different key lengths.

    Topic 5.3: Protecting Stored Data with Cryptography

  • OpenSSL

    A command-line tool that can encrypt and decrypt files with AES or RSA and generate key pairs. AES Crypt is another tool for files.

    Topic 5.3: Protecting Stored Data with Cryptography

  • Asymmetric encryption

    Encryption with a key pair: one key encrypts and only the other can decrypt. It lets people communicate securely without sharing a key first.

    Topic 5.4: Asymmetric Cryptography

  • Public and private keys

    To send someone a secret, encrypt with their public key; only their private key can decrypt it. If a private key leaks, make a new pair.

    Topic 5.4: Asymmetric Cryptography

  • Key length and keyspace

    An n-bit key has 2ⁿ possible keys, and random guessing finds it in 2ⁿ⁻¹ guesses on average. Each extra bit doubles the keyspace.

    Topic 5.4: Asymmetric Cryptography

  • Comparing key lengths

    Compare key lengths only within one algorithm: AES-256 beats AES-128 and RSA-4096 beats RSA-2048, but RSA and AES lengths can't be compared.

    Topic 5.4: Asymmetric Cryptography

  • RSA and ECC

    Two common asymmetric algorithms, RSA and elliptic curve cryptography. Asymmetric encryption also powers digital signatures and certificates.

    Topic 5.4: Asymmetric Cryptography

  • Secure by design

    Building security into every phase of making a product. Companies own customers' security outcomes, are open about problems and put security-first leaders in charge.

    Topic 5.5: Protecting Applications

  • Secure by default

    Security features come turned on out of the box, so a product is safe to use without extra setup.

    Topic 5.5: Protecting Applications

  • Control characters

    Characters an app uses to wrap user input, like the single quote, double quote and semicolon. Attackers slip them into input to change commands.

    Topic 5.5: Protecting Applications

  • Input sanitization

    Checking input against what's expected and removing or rejecting dangerous characters. It blocks many SQL injection, XSS and directory traversal attacks.

    Topic 5.5: Protecting Applications

  • Accounting

    Recording and monitoring user activity, like who opened, copied, moved or deleted which data. Its logs reveal unusual access.

    Topic 5.6: Detecting Attacks on Data and Applications

  • Honeypot

    A fake file that looks valuable, like fake card numbers. No one should open it, so any access triggers an alert right away.

    Topic 5.6: Detecting Attacks on Data and Applications

  • File hash check

    Hash a file, save the result, and hash it again later. A different hash means the file changed. Tools: sha256sum, Get-FileHash, shasum -a 256.

    Topic 5.6: Detecting Attacks on Data and Applications

  • Data loss prevention (DLP)

    A paid service that watches how data are accessed, used and sent across an organization to catch suspicious activity as it happens.

    Topic 5.6: Detecting Attacks on Data and Applications

  • Web log attack indicators

    Quotes, OR 1=1, -- and SQL words suggest SQL injection; HTML script tags suggest XSS; very long requests suggest buffer overflow; ../ suggests directory traversal.

    Topic 5.6: Detecting Attacks on Data and Applications